LIVE · cybersecurity feed
Live wire
security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

zeroday.news · 8d ago

British Prime Minister Andy Burnham has reappointed Liz Lloyd as the UK's cybersecurity minister, signaling continuity in national cyber policy despite a significant governmental restructuring that abolished the department previously overseeing the brief. Lloyd, who has led on cyber issues since September 2025, will retain her role while holding junior posts at both the Department for Digital, Culture, Media and Sport (DCMS) and the renamed Department for Business, Innovation, Science and Trade (DBIST).

The reappointment is notable as it goes against the trend of Burnham's initial cabinet selections, which largely removed allies of his predecessor, Keir Starmer. Lloyd, a close associate of Starmer and his former director of policy delivery, sits in the House of Lords as Baroness Lloyd of Effra. Her continued tenure is expected to prevent delays to the Cyber Security and Resilience Bill, which she is currently steering through the House of Lords. The bill, which cleared its second reading with cross-party support earlier this month, is scheduled for line-by-line scrutiny in September.

The Cyber Security and Resilience Bill aims to update regulations from 2018, expanding their scope to include more organizations and granting ministers powers to amend rules and issue directives to companies on national security grounds. Specifically, it brings data centers and managed service providers under regulatory purview and establishes incident reporting deadlines for operators of essential services such as energy, water, and healthcare. Lloyd was also the minister responsible when the government scaled back proposed cybersecurity protections for telecoms networks, measures initially developed in response to the Salt Typhoon espionage campaign, following industry lobbying regarding cost and practicality.

Burnham's government, formed after Starmer's resignation and a Labour Party leadership election, immediately dissolved the Department for Science, Innovation and Technology (DSIT), which had managed cyber policy since 2023. DSIT's functions have been divided: cyber policy and government digital services moved to DCMS, science to DBIST, and artificial intelligence policy along with the AI Security Institute to the Cabinet Office. This marks the first time AI security work has been separated from the broader cyber brief.

Industry observers have expressed concerns that this fragmentation could undermine the integrated approach to data, digital capabilities, and AI that was considered DSIT's primary strength. The placement of cyber policy within DCMS means it will share a department with politically sensitive cultural portfolios, including Online Safety and the renewal of the BBC Charter. While DCMS permanent secretary Susannah Storey is noted for her extensive experience in cyber issues, ministerial support is still deemed crucial for staff.

Lloyd had previously promised a National Cyber Action Plan, the government's strategy for defending the economy against state-backed and criminal hacking, for publication this summer. Its release, initially expected in early July, was delayed due to Starmer's resignation. A government spokesperson affirmed the importance of cybersecurity, stating that robust actions are being taken to protect the UK and improve resilience, with the Cyber Security and Resilience Bill designed to boost national cyber defenses. The spokesperson added that the redistribution of DSIT's functions recognizes technology as foundational to all future industry, culture, and public service delivery, rather than a separate economic facet.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]

ai

Microsoft, tech companies throw weight behind spread of open-source AI

Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.